GHSA-mr4r-hcgx-8p4h
Dashboard / Vulnerabilities / GHSA-mr4r-hcgx-8p4h
GHSA-mr4r-hcgx-8p4h
Summary: crewai-tools SSRF redirect bypass exposes internal services
Details: CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect to internal addresses or use DNS rebinding techniques to access internal services and cloud metadata endpoints.
References: https://nvd.nist.gov/vuln/detail/CVE-2026-62240, https://github.com/crewAIInc/crewAI/issues/6520, https://github.com/crewAIInc/crewAI/pull/6331, https://github.com/crewAIInc/crewAI/commit/5d4851eac797cafc45b726f65747fe2c9520fc42, https://github.com/crewAIInc/crewAI, https://github.com/crewAIInc/crewAI/releases/tag/1.15.1, https://www.vulncheck.com/advisories/crewai-ssrf-filter-bypass-via-http-redirect-in-scrape-tools
Affected packages
Package
Name: crewai-tools
Purl: pkg:pypi/crewai-tools
Affected ranges
Type: ECOSYSTEM
Events:
